Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5005 articles · 188942 vulns · 37/41 feeds (7d)
← Back to list
8.4
CVE-2026-15226PATCHED
Canonical · snapd

snapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restriction in Seccomp Templates

Description

A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default seccomp security templates generated by the engine to restrict system calls do not filter or reject process operations capable of creating or manipulating file execution flags with set-user-ID attributes. Consequently, an application running within a strictly confined snap environment can successfully compile or drop binaries and apply setuid properties to them. If a compromised or malicious process inside the snap sandbox executes these generated setuid binaries, it can potentially circumvent architectural sandboxing assumptions, drop intended restriction policies, or execute privileged actions inside the container namespace that should otherwise be strictly blocked. The vulnerability has been resolved by hardening the seccomp template engine to block the execution and creation of setuid executables by sandboxed snap processes.

Affected Products

VendorProductVersions
Canonicalsnapd0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
canonicallinuxcert_advisory90%
canonicalsnapcert_advisory90%

References

  • https://ubuntu.com/security/CVE-2026-15226(vdb-entry, issue-tracking)

Related News (2 articles)

Tier B
BSI Advisories21d ago
[NEU] [hoch] snapd: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB22d ago
CVE-2026-15226 | Canonical Ubuntu 16.04 LTS up to 24.04 LTS snap-confine sandbox
→ No new info (linked only)
CVSS 3.18.4 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
2.76.12.76+ubuntu26.04.32.76+ubuntu24.04.12.76+ubuntu22.04.12.67.1+20.04ubuntu1~esm22.61.4ubuntu0.18.04.1+esm32.61.4ubuntu0.16.04.1+esm3
CWECWE-250
PublishedJul 21, 2026
Last enriched22d agov2
Trending Score4
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-45893EXP
apparmor: Fix & Optimize table creation from possibly unaligned memory
Trending: 9
HIGHCVE-2026-8933
snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment Setup
Trending: 8
CRITICALCVE-2026-11386
ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code Execution
Trending: 3
MEDIUMCVE-2024-5300
AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbd
Trending: 3
MEDIUMCVE-2026-9494
ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Line
Trending: 2

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Updated: vendor, product, affectedVersions
Jul 21, 2026
Patch Available
Jul 22, 2026

Version History

v2
Last enriched 22d ago
v2Tier C22d ago

Added vendor as Canonical and product as snapd; updated affectedVersions to include specific Ubuntu LTS versions (16.04 through 24.04) instead of generic version 0.

vendorproductaffectedVersions
via VulDB
v122d ago

Initial creation